home / guides / Should You Tell Customers You Use AI? A Disclosure Guide

Guide

Should You Tell Customers You Use AI? A Disclosure Guide

What a handful of state laws already require, what the FTC watches for, and how to decide the rest for yourself.

Updated 2026-09-27 · 9 min read · yforest AI Labs

Key takeaways

  • There's no single federal law requiring AI disclosure to customers, but the legal landscape is moving fast and unevenly by state.
  • The FTC already enforces existing consumer protection law against deceptive AI claims and undisclosed AI-generated reviews.
  • A growing number of states — California among the first — have passed laws requiring disclosure for certain AI chatbot interactions.
  • Even without a legal requirement, proactive disclosure tends to build more customer trust than it costs.
  • This guide is general information, not legal advice — confirm your state's current requirements with an attorney before finalizing a disclosure approach.

"Do we have to tell customers we're using AI?" doesn't have one clean answer, because it depends on what the AI is doing, which state you're in, and whether any of it touches an existing consumer-protection rule. This guide walks through what's actually settled — the FTC's approach to deceptive AI claims and a handful of new state laws — and what's still a judgment call for your business.

There is no single U.S. federal law that requires every business to disclose AI use to every customer. What exists instead is a patchwork: the Federal Trade Commission enforcing existing consumer protection law against AI-related deception, and a growing number of states passing narrower laws aimed mostly at chatbots and AI-generated content. This is a fast-moving area — treat anything below as a snapshot, not a permanent answer, and verify current law for your state before finalizing a policy.

What the FTC already enforces

The FTC doesn't require AI disclosure as a blanket rule, but it does treat deceptive claims about AI the same way it treats other consumer fraud. Its enforcement actions give a clear picture of where the lines already are: a company that misrepresented the accuracy of an AI content-detection product, a business that published AI-generated reviews presented as genuine, and a company that claimed an "active listening" AI capability it didn't actually have.

The pattern behind FTC actions

Every one of these cases involved a false or misleading claim about what the AI does or where it came from — not simply using AI. The lesson for a small business: describe your AI accurately, and disclose when content (like a review) is AI-generated rather than letting it pass as organic.

A few states have gone further

Several states have passed AI-specific disclosure laws, most focused on chatbots that could otherwise be mistaken for a human. California's SB 243 is one of the clearer examples: it requires operators of companion-style AI chatbots to give a "clear and conspicuous" notice that the user is talking to AI when a reasonable person might otherwise believe they're talking to a human, with additional requirements when the platform knows the user is a minor. Other states, including New York, Maine, and Utah, have passed their own related legislation in the same period.

Where you might be coveredWhat to check
Customer-facing chatbot that could be mistaken for a humanWhether your state has a disclosure law like California's SB 243
AI-generated reviews, testimonials, or marketing claimsFTC rules on deceptive endorsements and accuracy claims
AI used in hiring, lending, housing, or similarly regulated decisionsIndustry- and state-specific AI or automated-decision laws, which vary widely

Because this area changes quickly and varies by state, treat the table above as a starting point for a conversation with your attorney, not a complete list. A law passed in one state this year may be followed by similar bills elsewhere well before you'd expect.

Why disclose even where it's not required

Outside of any legal requirement, there's a practical reason to lean toward disclosure: customers who find out later, rather than being told upfront, tend to react more negatively to the same AI use. A brief, plainly worded disclosure — "you're chatting with our AI assistant" — rarely costs a business anything in the moment and tends to prevent a much worse reaction if a customer figures it out on their own.

Keep it short

Disclosure doesn't need a paragraph of explanation. A single clear sentence at the point of interaction does the job without making the interaction feel clinical.

A simple way to decide for your business

  • Chatbot or voice AI that could be mistaken for a human? Disclose clearly, and check whether your state has a specific law like California's SB 243.
  • AI-generated review, image, or testimonial? Disclose it as AI-generated — this is squarely inside what the FTC already treats as a deception issue if left unlabeled.
  • AI-assisted internal drafting that a person reviews and sends as their own communication? Generally a judgment call, not a legal requirement — many businesses don't disclose this level of AI assistance, similar to not disclosing which software drafted a document.
  • Marketing claims about your product's AI features? Make sure they're accurate — the FTC has pursued cases over AI capability claims that didn't hold up.

Writing a disclosure that doesn't feel clinical

A disclosure line can technically satisfy a requirement while still landing badly with a customer, if it reads like a legal disclaimer instead of a normal sentence. The goal is a line a real person would actually say out loud, not boilerplate copied from a template.

Sample disclosure lines
Chat widget, opening message: Hi! You're chatting with our AI assistant. I can help with most questions right away, and I'll bring in a person if you need one. Phone system, before an AI voice agent: You're speaking with an automated assistant today. Say "representative" any time to reach a person. AI-generated review or testimonial label: This summary was generated with AI assistance based on verified customer feedback. Marketing copy referencing an AI feature: Our [feature name] uses AI to [specific, accurate description of what it does] — always describe capability plainly, without exaggerating what the AI can do.

Notice each example does two things at once: states plainly that AI is involved, and gives the customer an obvious next step if they'd rather deal with a person. That second part usually matters more to the customer experience than the disclosure itself.

Industries with extra disclosure considerations

A handful of industries carry disclosure or transparency expectations well beyond the general rules covered above, usually layered on top of existing sector regulation rather than created specifically for AI.

IndustryWhat to watch for
Healthcare and dentalExisting patient privacy and communication rules apply to AI tools the same way they apply to any other software — see our HIPAA and AI guide.
Financial services and insuranceDisclosure requirements around automated decisions (like credit or eligibility) are often separate from general AI transparency rules — see our financial and insurance data guide.
Legal servicesClient confidentiality obligations can interact with AI disclosure in ways general businesses don't face — see our law firm AI guide.

If your business sits in one of these categories, treat the general guidance in this article as a starting point and confirm specifics with counsel familiar with your industry — the stakes for getting disclosure wrong are typically higher in regulated fields.

Keeping this current as the law changes

State legislatures are actively working on AI transparency bills, and the pace of new legislation has been fast enough that a guide like this one is best treated as a snapshot rather than a permanent reference. A practical way to stay current without hiring a compliance service: set a calendar reminder every six months to search for "[your state] AI chatbot disclosure law" and "[your state] AI transparency requirements," and skim the results for anything new. Pair that with the quarterly AI governance review from our governance starter kit, so disclosure requirements get revisited on the same schedule as everything else.

If your business operates in more than one state, treat this as a per-state question rather than assuming your home state's rules cover everywhere you do business — a customer-facing chatbot reaching residents of a state with its own disclosure law may need to meet that state's requirements regardless of where your company is based.

Common mistakes

  • Assuming no federal law means no risk. State laws and FTC deception rules already apply in specific situations, even without a blanket federal disclosure statute.
  • Treating disclosure as one-size-fits-all. A chatbot disclosure and a marketing-claim disclosure solve different problems and don't require the same wording.
  • Overcomplicating the disclosure itself. A short, plain sentence usually works better than a lengthy explanation nobody reads.
  • Publishing AI-generated reviews or testimonials without labeling them. This is one of the clearest categories the FTC has already acted on.
  • Not revisiting this as laws change. This is one of the fastest-moving areas of AI regulation — a policy set once and never revisited can fall out of date within a year.

Disclosure decisions often overlap with your human review process for customer-facing AI output — if a response needs review before it goes out, it's also a good moment to confirm whether it needs a disclosure. For the underlying policy language, see our AI acceptable use policy guide.

◆ Small Business AI Kickstart

Get AI ready today.
Before it's too late.

yforest AI Labs comes to your company, trains your team, and ships your first tools.

FAQ

Is there a federal law requiring businesses to disclose AI use to customers?

Not a single blanket federal disclosure law as of this writing. The FTC instead enforces existing consumer protection rules against deceptive AI claims, and several states have passed their own, narrower disclosure laws — this is a shifting area, so check current requirements for your state before finalizing your approach.

Does California require businesses to disclose chatbot use?

California's SB 243 creates disclosure obligations specifically for companion-style AI chatbots, including telling users clearly when a reasonable person might otherwise think they're talking to a human. It's one example of the kind of state-specific rule that's expanding — verify what applies to your business and state with an attorney.

If there's no law requiring it, why disclose at all?

Trust. Customers who find out later that a response, image, or review was AI-generated without being told tend to react more negatively than if they'd known upfront. Proactive disclosure, done briefly and without over-explaining, tends to build more trust than it costs.

Do we need to disclose AI use in marketing content, not just customer service?

The FTC has taken enforcement action over deceptive AI-related marketing claims, such as misrepresenting a product's AI accuracy or publishing AI-generated reviews without disclosure. Any claim about what your AI does should be accurate and any AI-generated review or testimonial should be disclosed as such.

What's a simple disclosure that works for most small businesses?

A short, plain line at the point of interaction — "You're chatting with our AI assistant" or a brief note on AI-assisted content — covers most situations without needing legal language, though your state's specific requirements may call for more.

Sources

  1. Federal Trade Commission — Artificial Intelligence
  2. Future of Privacy Forum — Understanding the New Wave of Chatbot Legislation (California SB 243 and Beyond)

This guide is general information, not legal advice. Have a qualified attorney review any policy before you adopt it.